Re: Routing across internal subnets



James Brubaker wrote:
We have a gre tunnel between this main site and the remote sites on our Cisco routers in order to connect the separate subnets for the smaller remote locations. Individual VPN's from each PC are not really feasible, and the sites do not have a servers set up to do VPN's just the routers that do the tunnel.

Our end goal is the following (for one location):

Remote Site - Cisco Router - Cisco Tunnel Endpoint (Remote) - 192.168.20.0 - 192.168.20.1 - 192.168.100.2 -

Cisco Tunnel Endpoint (Main Office) -Cisco Router - SBS Server (External Nic) - 192.168.100.1 - 10.10.10.1 - 10.10.10.2 -

SBS Server (Internal Subnet)
192.168.0.0

In essence, that the external 192.168.20.0 subnet can communicate with the 192.168.0.0 Subnet.

Are thoughts are that we may need a 3rd NIC to do a static route (although current configured static routes do not work), a Vlan in the 192.168.0.0 subnet on the Cisco Router, or possibly ISA.

Move the SBS to one NIC mode. SBS with two NICs, whether with ISA or not, is a firewall, and is specifically designed not to allow access to its LAN side from the 'outside'. You can open ports to allow access, but by the time you've opened enough to allow workstations to operate with it, there's absolutely no point in having two NICs.
.



Relevant Pages

  • Re: IP Config with 2 NICs Wizard dont work, Static dont work!
    ... want to beat a dead horse here but the internal and external NICs CANNOT ... Internet and Email on Left Panel and set the Address to 192.168.16.2 Leave ... If you want to understand IP subnetting and subnet masks please get a book ... Or should I move the static IP routers over to ...
    (microsoft.public.windows.server.sbs)
  • Re: HSRP and Policy Route
    ... routers think they are the local owner of the 5.1 subnet, ... now I am taking only default route from the ISP's but I guess if I ... So I'm assuming you have a switch in the 10.X network that goes to the ... of the subnet as you are saying that when Core 2 owns the 5.X network, ...
    (comp.dcom.sys.cisco)
  • Re: another vpn wins site to site to site problem*
    ... you effectively have three segments/subnets linked by routers. ... The current advice is to delete the DisableNetbiosOverTcpip ... subnet for the RAS/VPN interfaces to solve the browsing problem. ... I have a central server ...
    (microsoft.public.windows.server.networking)
  • Re: I want to link 2 lans at home
    ... > have to change the least significant bit of the sub net mask. ... So that for the original poster to add the two networks ... Anyway, if the two linksys' were just routers, just changing the subnet ... puttin everything on a /22 subnet as discussed previously in the thread. ...
    (comp.os.linux.networking)
  • Re: Accessing Multiple ISPs on the fly
    ... ADSL connection with a second ISP. ... > I am assuming that your WAN connections are going through two differnet ... > workstation to the other subnet if it is used to reset the IP configuration. ... > Its the routers that care. ...
    (microsoft.public.windowsxp.network_web)